A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.
| Score | Percentile |
|---|---|
| 0.68% | 71.51% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 7.5 | 3.1 | — |
|
| 8.7 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-7527-8855-9cf8 ↗ |
| CVE | CVE-2022-2255 ↗ |
| CWE id | Name |
|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| pip | mod-wsgi | < 4.9.3 | 4.9.3 | — |